Vulnerability Name CVE Severity
TYPO3 Improper Input Validation Vulnerability (CVE-2019-11832) CVE-2019-11832
TYPO3 Improper Input Validation Vulnerability (CVE-2020-15099) CVE-2020-15099
TYPO3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2019-19848) CVE-2019-19848
TYPO3 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2010-3668) CVE-2010-3668
TYPO3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-4855) CVE-2009-4855
TYPO3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-3662) CVE-2010-3662
TYPO3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2013-1842) CVE-2013-1842
TYPO3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2019-19850) CVE-2019-19850
TYPO3 Insufficient Session Expiration Vulnerability (CVE-2022-31050) CVE-2022-31050
TYPO3 Other Vulnerability (CVE-2006-6690) CVE-2006-6690
TYPO3 Other Vulnerability (CVE-2007-1081) CVE-2007-1081
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3714) CVE-2010-3714
Typo3 Restler 1.7.0 Local File Disclosure
TYPO3 Uncontrolled Recursion Vulnerability (CVE-2021-21359) CVE-2021-21359
TYPO3 Uncontrolled Recursion Vulnerability (CVE-2022-23500) CVE-2022-23500
TYPO3 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2010-3663) CVE-2010-3663
TYPO3 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-14251) CVE-2017-14251
TYPO3 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2021-21357) CVE-2021-21357
Ubiquiti Unifi Log4Shell RCE CVE-2021-44228
Umbraco CMS local file inclusion
Umbraco CMS remote code execution
Umbraco CMS TemplateService remote code execution CVE-2013-4793
Unauthenticated Arbitrary File Read vulnerability in VMware vCenter
Unauthenticated OGNL injection in Confluence Server and Data Center CVE-2021-26084
Unauthenticated Remote Code Execution via JSONWS in Liferay 6.1 (LPS-88051)
Unauthenticated Remote Code Execution via JSONWS in Liferay 7.2.0 CE GA1 CVE-2020-0618 CVE-2020-7961
Unauthenticated remote code execution vulnerability in Confluence Server and Data Center CVE-2022-26134
Uncontrolled format string
Underscore.js Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-23358) CVE-2021-23358
Undertow CVE-2022-1259 Vulnerability (CVE-2022-1259) CVE-2022-1259
Undertow CVE-2023-3223 Vulnerability (CVE-2023-3223) CVE-2023-3223
Undertow Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-3859) CVE-2021-3859
Undertow Improper Input Validation Vulnerability (CVE-2020-1757) CVE-2020-1757
Undertow Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2020-10705) CVE-2020-10705
Undertow Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Vulnerability (CVE-2017-12165) CVE-2017-12165
Undertow Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2017-2670) CVE-2017-2670
Undertow Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2023-1108) CVE-2023-1108
Undertow Missing Authorization Vulnerability (CVE-2019-10184) CVE-2019-10184
Undertow Unchecked Return Value Vulnerability (CVE-2022-1319) CVE-2022-1319
Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2019-14888) CVE-2019-14888
Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2019-19343) CVE-2019-19343
Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2021-3629) CVE-2021-3629
Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2021-3690) CVE-2021-3690
Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2022-2053) CVE-2022-2053
Unprotected phpMyAdmin interface
Unrestricted access to Caddy API interface
Unrestricted access to Haproxy Data Plane API
Unrestricted access to Kong Gateway API
Unrestricted access to NGINX+ API interface (read write)
Unrestricted access to Odoo DB manager
Unrestricted file upload vulnerability in ofc_upload_image.php CVE-2009-4140
Unsafe use of Reflection
Uploadify arbitrary file upload
User controllable script source
uWSGI Path Traversal vulnerability CVE-2018-7490
uWSGI Unauthorized Access Vulnerability
Vanilla Forums Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-1000432) CVE-2017-1000432
Vanilla Forums CVE-2013-3528 Vulnerability (CVE-2013-3528) CVE-2013-3528
Vanilla Forums Deserialization of Untrusted Data Vulnerability (CVE-2018-19499) CVE-2018-19499
Vanilla Forums Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3613) CVE-2011-3613
Vanilla Forums Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-10073) CVE-2016-10073
Vanilla Forums Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2013-3527) CVE-2013-3527
Varnish Cache Integer Overflow or Wraparound Vulnerability (CVE-2017-12425) CVE-2017-12425
Varnish Cache Other Vulnerability (CVE-2013-4090) CVE-2013-4090
Varnish Cache Other Vulnerability (CVE-2015-8852) CVE-2015-8852
Varnish Cache Reachable Assertion Vulnerability (CVE-2019-15892) CVE-2019-15892
vBSEO 3.6.0 PHP code injection CVE-2012-5223
vBulletin 4 (up to 4.1.2) search.php SQL injection
vBulletin 5 CONNECT remote code execution
vBulletin 5.1.2 SQL injection CVE-2014-5102
vBulletin 5.6.1 nodeId SQL injection CVE-2020-12720
vBulletin 5.x 0day pre-auth RCE
vBulletin customer number disclosure CVE-2013-6129
vBulletin PHP object injection vulnerability
vBulletin Pre-Auth RCE Vulnerability CVE-2020-17496